CVE-2025-5464
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-08

Last updated on: 2025-07-15

Assigner: ivanti

Description
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-08
Last Modified
2025-07-15
Generated
2026-05-07
AI Q&A
2025-07-08
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 16 associated CPEs
Vendor Product Version / Range
ivanti connect_secure to 22.7 (exc)
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
ivanti connect_secure 22.7
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-532 The product writes sensitive information to a log file.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability involves the insertion of sensitive information into a log file in Ivanti Connect Secure versions before 22.7R2.8. A local authenticated attacker can exploit this to obtain sensitive information from the log files.


How can this vulnerability impact me? :

The vulnerability can lead to unauthorized disclosure of sensitive information to a local authenticated attacker, potentially compromising confidentiality without affecting integrity or availability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart